What’s going on under the hood of the Judy apps we wrote about last month? We had a look – and didn’t like what we found
Jaff Malware Probe Uncovers Link to Cybercrime Marketplace
Researchers have discovered a shared backend infrastructure between the Jaff ransomware and a black market carder shop.
Fireball Malware Infects 250 Million Computers Worldwide
A massive malware campaign has already infected 250 million Windows and Mac OS computers worldwide.
WikiLeaks Dumps CIA Patient Zero Windows Implant
Pandemic is a Windows implant built by the CIA that turns file servers into Patient Zero on a local network, infecting machines requesting files with Trojanized replacements.
Threatpost News Wrap, June 2, 2017
Mike Mimoso and Chris Brook discuss the news of the week, including the ShadowBrokers crowdfunding attempt, errors in WannaCry, a new Wikileaks dump, last week’s Samba vulnerability, and the OneLogin breach.
EternalBlue Exploit Spreading Gh0st RAT, Nitol
FireEye said threat actors are using the NSA’s EternalBlue exploit of the same Microsoft SMBv1 vulnerability as WannaCry to spread Nitol and Gh0st RAT.
WannaCry Development Errors Enable File Recovery
Researchers at Kaspersky Lab have found a number of programming errors in the WannaCry ransomware code that put file recovery within reach of sysadmins.
Hackers shelve crowdfunding drive for Shadow Brokers exploits
‘Legal reasons’ cited for decision to drop the plan to crowdfund a security community subscription to a promised monthly dump of exploits
Wolf in sheep’s clothing: a SophosLabs investigation into delivering malware via VBA
SophosLabs gets under the skin of the bad guys’ latest attempt to drop ransomware on to your PCs
ShadowBrokers Put Price on Monthly Zero Day Leaks
The ShadowBrokers announced details on how to subscribe to its Monthly Dump Service, which is available for 100 Zcash.